Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

proftpd-mysql-1.3.8d-4.el9 RPM for aarch64

From EPEL 9 Testing for aarch64 / Packages / p

Name: proftpd-mysql Distribution: Fedora Project
Version: 1.3.8d Vendor: Fedora Project
Release: 4.el9 Build date: Tue Jul 28 19:59:08 2026
Group: Unspecified Build host: buildvm-a64-43.rdu3.fedoraproject.org
Size: 69440 Source RPM: proftpd-1.3.8d-4.el9.src.rpm
Packager: Fedora Project
Url: http://www.proftpd.org/
Summary: Module to add MySQL support to the ProFTPD FTP server
Module to add MySQL support to the ProFTPD FTP server.

Provides

Requires

License

GPL-2.0-or-later

Changelog

* Wed Jul 22 2026 Paul Howarth <paul@city-fan.org> - 1.3.8d-4
  - Address another avenue for SQL injection, via custom SQLUserInfo queries
    (https://github.com/proftpd/proftpd/issues/2052#issuecomment-4489110598)
  - Fix SFTP request payload length underflow calculation in mod_sftp
    (CVE-2026-53994, https://github.com/proftpd/proftpd/issues/2115)
  - Exercise caution when reading the client-provided file size for SCP uploads,
    as it could possibly overflow our size type (CVE-2026-63091)
  - Authenticated SFTP sessions could overflow the SFTP packet buffer
    (CVE-2026-63090, https://github.com/proftpd/proftpd/issues/2190)
  - Add mod_procfs, enabled by default, to address CVE-2026-35025 (ACL bypass via
    /proc/self/root path prefix); this module disallows file accesses via procfs
    filesystems
* Mon May 11 2026 Paul Howarth <paul@city-fan.org> - 1.3.8d-3
  - Additional escaping for avoidance of SQL injection issues with %{note:...}
    and %{env:...}; these are on top of the existing fix for CVE-2026-42167 in
    1.3.9a
  - Fix for SQL Injection in mod_wrap2_sql via reverse DNS hostname
    (CVE-2026-44331, rhbz#2466899, https://github.com/proftpd/proftpd/issues/2057)
* Wed Apr 29 2026 Paul Howarth <paul@city-fan.org> - 1.3.8d-2
  - Fix potential SQL injection via mod_sql (CVE-2026-42167)
    - https://github.com/proftpd/proftpd/issues/2052
* Tue Mar 18 2025 Paul Howarth <paul@city-fan.org> - 1.3.8d-1
  - Update to 1.3.8d
    - Use of HideNoAccess for SFTP sessions can lead to segfault and/or
      unexpected behaviour (GH#1855)
    - SFTP channel allocations can lead to high memory utilization over time
      (GH#1876)
    - Avoid NULL pointer dereferences in mod_ls (GH#1866, CVE-2024-57392)
* Thu Feb 13 2025 Paul Howarth <paul@city-fan.org> - 1.3.8c-2
  - Avoid NULL pointer dereferences in mod_ls (CVE-2024-57392)
    - https://github.com/proftpd/proftpd/issues/1866
* Thu Dec 12 2024 Paul Howarth <paul@city-fan.org> - 1.3.8c-1
  - Update to 1.3.8c
    - Using FTPS after upgrading from 1.3.8a to 1.3.8b lead to crash (GH#1770)
    - Bad handling of lack of extended attributes lead to SFTP out of memory
      error (GH#1785)
    - mod_sftp_sql logged "header value too long" due to unexpected key header
      text (GH#1529)
    - SSH ECDSA host key algorithms were not used as expected despite configuring
      appropriate key (GH#1839)
    - RADIUS Message-Authenticator verification failed with ProFTPD mod_radius
      (GH#1840)
    - Supplemental group inheritance granted unintended access to GID 0 due to
      lack of supplemental groups from mod_sql (GH#1830)
* Tue Nov 19 2024 Paul Howarth <paul@city-fan.org> - 1.3.8b-4
  - Fix RADIUS Message-Authenticator verification in mod_radius
    - https://github.com/proftpd/proftpd/issues/1840
    - https://bugzilla.redhat.com/show_bug.cgi?id=2325448

Files

/usr/lib/.build-id
/usr/lib/.build-id/13
/usr/lib/.build-id/13/e68b203c4145d61559645b613f75ec73b3da8b
/usr/libexec/proftpd/mod_sql_mysql.so


Generated by rpm2html 1.8.1

Fabrice Bellet, Wed Jul 29 03:55:55 2026